An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper
History

Mon, 12 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Kde
Kde kde
Smb4k
Smb4k smb4k
Vendors & Products Kde
Kde kde
Smb4k
Smb4k smb4k

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Description An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper
Title Local users can perform arbitrary unmounts via smb4k mount helper due to lack of input validation
Weaknesses CWE-88
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published: 2026-01-08T14:25:44.172Z

Updated: 2026-01-08T15:55:57.881Z

Reserved: 2025-11-19T08:52:54.076Z

Link: CVE-2025-66002

cve-icon Vulnrichment

Updated: 2026-01-08T15:55:51.396Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-08T15:15:43.590

Modified: 2026-01-08T18:08:18.457

Link: CVE-2025-66002

cve-icon Redhat

No data.